QID 730080
Date Published: 2021-05-20
QID 730080: HPE Edgeline Infrastructure Manager Authentication Bypass Vulnerability (HPESBGN04124)
The HPE Edgeline Infrastructure Manager Software (EIM) makes it simple to deploy and manage HPE Edgeline systems in any location.
Affected Versions:
HPE Edgeline Infrastructure Manager Software (EIM) prior to 1.22.
QID Detection Logic:(Unauthenticated)
This QID will send a GET request to "/redfish/v1/" to check vulnerabile version of EIM.
The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration.
Solution
Customers are advised to update HPE Edgeline Infrastructure Manager Software (EIM) to 1.22 or later to fix this vulnerability.
For more information,visit HPESBGN04124.
For more information,visit HPESBGN04124.
Vendor References
- HPE EdgeLine(HPESBGN04124) -
support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=emr_na-hpesbgn04124en_us
CVEs related to QID 730080
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| HPESBGN04124 |
|